44 push :
55 branches :
66 - main
7+ - beta
78 workflow_dispatch :
89 inputs :
910 ref :
10- description : " Git ref to build and tag the image ( branch, tag, or commit SHA) "
11+ description : " Docker tag / ref (no slashes) to build and tag the image: branch, tag, or commit SHA"
1112 type : string
1213 required : true
1314
@@ -31,16 +32,33 @@ jobs:
3132 ref : ${{ github.event_name == 'workflow_dispatch' && github.event.inputs.ref != '' && github.event.inputs.ref || github.ref }}
3233
3334 - name : Set image tag
34- id : set-tag
35+ shell : bash
3536 run : |
36- if [ -n "${{ github.event.inputs.ref }}" ]; then
37- echo "IMAGE_TAG=${{ github.event.inputs.ref }}" >> $GITHUB_ENV
37+ if [ -n "$INPUT_REF" ]; then
38+ # Whole-string match (not per-line like grep -x): the ref must be exactly one
39+ # Docker tag, so a newline can't smuggle extra lines into $GITHUB_ENV.
40+ tag_re='^[A-Za-z0-9_][A-Za-z0-9_.-]{0,127}$'
41+ if ! [[ "$INPUT_REF" =~ $tag_re ]]; then
42+ echo "ref is not a valid Docker tag: $INPUT_REF" >&2
43+ exit 1
44+ fi
45+ echo "IMAGE_TAG=$INPUT_REF" >> "$GITHUB_ENV"
46+ elif [ "$EVENT_NAME" = "push" ] && [ "$REF_NAME" = "beta" ]; then
47+ # Beta pushes publish only :beta and must never touch :latest.
48+ echo "IMAGE_TAG=beta" >> "$GITHUB_ENV"
49+ elif [ "$EVENT_NAME" = "push" ] && [ "$REF_NAME" = "main" ]; then
50+ echo "IMAGE_TAG=latest" >> "$GITHUB_ENV"
3851 else
39- echo "IMAGE_TAG=latest" >> $GITHUB_ENV
52+ echo "Unexpected trigger $EVENT_NAME on $REF_NAME; refusing to pick a tag" >&2
53+ exit 1
4054 fi
41- echo "PLATFORM_PAIR=${platform//\//-}" >> $GITHUB_ENV
55+ echo "PLATFORM_PAIR=${platform//\//-}" >> " $GITHUB_ENV"
4256 env :
4357 platform : ${{ matrix.platform }}
58+ INPUT_REF : ${{ github.event.inputs.ref }}
59+ EVENT_NAME : ${{ github.event_name }}
60+ REF_NAME : ${{ github.ref_name }}
61+ LC_ALL : C
4462
4563 - name : Log in to DockerHub
4664 uses : docker/login-action@v3
6078 platforms : ${{ matrix.platform }}
6179 # Push by digest only; the merge job tags the final manifest.
6280 outputs : type=image,name=cbioportal/mcp,push-by-digest=true,name-canonical=true,push=true
63- cache-from : type=gha,scope=${{ env.PLATFORM_PAIR }}
64- cache-to : type=gha,scope=${{ env.PLATFORM_PAIR }},mode=max
81+ cache-from : type=gha,scope=${{ env.PLATFORM_PAIR }}-${{ env.IMAGE_TAG }}
82+ cache-to : type=gha,scope=${{ env.PLATFORM_PAIR }}-${{ env.IMAGE_TAG }} ,mode=max
6583
6684 - name : Export digest
6785 run : |
@@ -82,12 +100,31 @@ jobs:
82100 runs-on : ubuntu-latest
83101 steps :
84102 - name : Set image tag
103+ shell : bash
85104 run : |
86- if [ -n "${{ github.event.inputs.ref }}" ]; then
87- echo "IMAGE_TAG=${{ github.event.inputs.ref }}" >> $GITHUB_ENV
105+ if [ -n "$INPUT_REF" ]; then
106+ # Whole-string match (not per-line like grep -x): the ref must be exactly one
107+ # Docker tag, so a newline can't smuggle extra lines into $GITHUB_ENV.
108+ tag_re='^[A-Za-z0-9_][A-Za-z0-9_.-]{0,127}$'
109+ if ! [[ "$INPUT_REF" =~ $tag_re ]]; then
110+ echo "ref is not a valid Docker tag: $INPUT_REF" >&2
111+ exit 1
112+ fi
113+ echo "IMAGE_TAG=$INPUT_REF" >> "$GITHUB_ENV"
114+ elif [ "$EVENT_NAME" = "push" ] && [ "$REF_NAME" = "beta" ]; then
115+ # Beta pushes publish only :beta and must never touch :latest.
116+ echo "IMAGE_TAG=beta" >> "$GITHUB_ENV"
117+ elif [ "$EVENT_NAME" = "push" ] && [ "$REF_NAME" = "main" ]; then
118+ echo "IMAGE_TAG=latest" >> "$GITHUB_ENV"
88119 else
89- echo "IMAGE_TAG=latest" >> $GITHUB_ENV
120+ echo "Unexpected trigger $EVENT_NAME on $REF_NAME; refusing to pick a tag" >&2
121+ exit 1
90122 fi
123+ env :
124+ INPUT_REF : ${{ github.event.inputs.ref }}
125+ EVENT_NAME : ${{ github.event_name }}
126+ REF_NAME : ${{ github.ref_name }}
127+ LC_ALL : C
91128
92129 - name : Download digests
93130 uses : actions/download-artifact@v4
@@ -108,8 +145,8 @@ jobs:
108145 - name : Create multi-arch manifest
109146 working-directory : /tmp/digests
110147 run : |
111- docker buildx imagetools create -t cbioportal/mcp:${{ env. IMAGE_TAG }} \
148+ docker buildx imagetools create -t " cbioportal/mcp:$IMAGE_TAG" \
112149 $(printf 'cbioportal/mcp@sha256:%s ' *)
113150
114151 - name : Inspect
115- run : docker buildx imagetools inspect cbioportal/mcp:${{ env. IMAGE_TAG }}
152+ run : docker buildx imagetools inspect " cbioportal/mcp:$IMAGE_TAG"
0 commit comments